Description
F-RevoCRM contains a cross-site scripting vulnerability. If a user views a crafted page while logged in to the affected product, unintended operations may be performed.
Published: 2026-08-20
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an XSS flaw in F‑RevoCRM. An attacker can inject malicious script into a page that a logged‑in user will view. The script runs in the context of the authenticated session and can potentially perform unintended operations such as manipulating data or executing functions within the application.

Affected Systems

F‑RevoCRM from Thinkingreed Inc. The affected version is not specified in the CVE data, so all installations of the product should be considered potentially vulnerable. The vendor is Thinkingreed Inc.’s F‑RevoCRM.

Risk and Exploitability

The CVSS score is 5.1, indicating moderate impact. The EPSS score is less than 1%, signaling a very low probability of exploitation at the time of analysis. The vulnerability is not listed in CISA KEV, so no current known attacks are documented. The likely attack vector requires a victim to view a crafted resource while logged in, implying the need for social engineering or a malicious link. An attacker would need the victim to be authenticated and to open the page containing the injected script.

Generated by OpenCVE AI on August 20, 2026 at 22:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to the latest F‑RevoCRM release that removes the XSS flaw
  • Deploy a Content Security Policy that restricts inline scripts and script sources
  • Apply strict input validation and output encoding to all user-controllable fields to eliminate injection vectors

Generated by OpenCVE AI on August 20, 2026 at 22:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Title F‑RevoCRM Cross‑Site Scripting Enables Unintended Operations

Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Thinkingreed Inc.
Thinkingreed Inc. f-revocrm
Vendors & Products Thinkingreed Inc.
Thinkingreed Inc. f-revocrm

Thu, 20 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Description F-RevoCRM contains a cross-site scripting vulnerability. If a user views a crafted page while logged in to the affected product, unintended operations may be performed.
Weaknesses CWE-79
References
Metrics cvssV3_0

{'score': 6.1, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Thinkingreed Inc. F-revocrm
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-08-27T16:06:16.256Z

Reserved: 2026-08-06T06:09:13.766Z

Link: CVE-2026-71368

cve-icon Vulnrichment

Updated: 2026-08-27T15:40:58.583Z

cve-icon NVD

Status : Deferred

Published: 2026-08-20T07:16:32.400

Modified: 2026-08-28T16:09:10.947

Link: CVE-2026-71368

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T22:15:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')